Announcement

Collapse
No announcement yet.

Firewall not blocking ICMP

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Firewall not blocking ICMP

    I have a firewall rule setup to block all traffic if my VPN tunnel is down. It seems to be working for the most part but ICMP is not blocked. I figured all traffic would be blocked. I'm not specifying any protocols, but I did create a test rule blocking ICMP and it still wasn't blocked. Is this normal behavior?

    Click image for larger version

Name:	2022-09-07 09_25_36-Untangle - untangle715 - Brave.png
Views:	1
Size:	8.8 KB
ID:	387359

    Click image for larger version

Name:	2022-09-07 09_24_12-Untangle - untangle715 - Brave.png
Views:	1
Size:	4.3 KB
ID:	387360

  • #2
    Originally posted by MP715 View Post
    I have a firewall rule setup to block all traffic if my VPN tunnel is down. It seems to be working for the most part but ICMP is not blocked. Is this normal behavior?
    Last edited by jcoffin; 09-07-2022, 08:21 AM.
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email [email protected]

    Comment


    • #3
      Originally posted by jcoffin View Post
      Originally posted by MP715 View Post
      I have a firewall rule setup to block all traffic if my VPN tunnel is down. It seems to be working for the most part but ICMP is not blocked. Is this normal behavior?
      https://forums.untangle.com/ng-firew...tml#post255093
      Got it. Thanks for your reply. I'm really bad at searching the forums before posting! So, I should have used Filter Rules all along and no longer need those firewall rules above? It's working great!
      Last edited by MP715; 09-07-2022, 08:27 AM.

      Comment


      • #4
        Originally posted by MP715 View Post
        …I should have used Filter Rules all along and no longer need those firewall rules above?
        I recommend comparing the conditions available in Filter Rules with those available to the Firewall app. If a rule can be created in Filter Rules, it should be. They're best at blocking any layer-3 attributes: IP addresses, interfaces, &c. ('Anything based on a number', I usually say.)

        In most cases, the Firewall app is used for:
        • geo-IP blocking, used to block traffic to or from whole countries
        • username-based blocking, including blocking based on AD groups
        Græme Ravenscroft • Technical Marketing Engineer
        ('gram', like the unit of measurement)
        he/him
        How can we make Arista ETM products better?

        Comment

        Working...
        X
        😀
        🥰
        🤢
        😎
        😡
        👍
        👎